Fariin

Privacy policy

Last updated 3 August 2026

This explains what Fariin stores, what it cannot read, which permissions it asks your phone for, who else touches your data, and how to get rid of all of it. It is written to be read, not to be survived.

The short version

The contents of your messages and calls are encrypted so that only you and the person you are talking to can read or hear them. We cannot. What we hold is the small amount of information needed to run an account and deliver a message: who you are, which devices you use, and when something was sent.

We have never sold data about you and we will not. There are no ads in Fariin, no advertising companies in it, and nothing in this policy permits anyone to buy access to you.

Permissions the app asks for

iOS asks before Fariin can touch any of these, and you can say no to every one of them. Saying no switches off the feature that needs it and nothing else. You can change your mind later in the iPhone Settings app under Fariin.

PermissionAsked whenWhat it is used for
PhotosThe first time you attach a pictureReading the picture you picked. Fariin does not scan your library or look at photos you did not choose.
Save to photosThe first time you save a picture from a chatWriting that one picture to your camera roll.
CameraThe first time you take a photo in a chat or start a video callTaking the photo, and your video during a call.
MicrophoneThe first time you record a voice message or start a callRecording that message, and your voice during a call.
LocationOnly if you choose to send a locationReading your position once so it can be put in that message. Fariin does not track you in the background and does not ask for always-on location.
Face IDOnly if you turn on the app lockUnlocking the app. The check happens on your phone and Fariin never receives your face data.
NotificationsWhen you first sign inWaking your phone for a message or an incoming call.

Fariin never asks for your contacts. Your address book is not read and not uploaded. Most messengers upload it to work out who you know. This one does not, so there is no copy of your social circle on our servers to lose, subpoena or leak.

What we store

Your account

A username, a display name, and the phone number or email address you signed up with. If you add a profile photo, that too.

Your profile photo and display name are not end to end encrypted. They have to be readable by people allowed to see your profile, so treat them as visible to anyone you chat with.

Messages and media

Message text is encrypted on your phone before it leaves and decrypted on the recipient's phone. We store the encrypted result so it can be delivered, plus what is needed to deliver it: who sent it, who it is for, and when. Photos, video, voice notes and files are handled the same way. If you turn on disappearing messages, the message is removed when the timer runs out.

Calls

Voice and video are encrypted between the two phones. Most calls connect directly. When two phones cannot reach each other, which is common on mobile networks, the encrypted audio and video is relayed through a server so the call can happen at all. The relay passes it on and cannot open it. We keep a record that a call took place, between whom, and how long it lasted.

Stories

Visible to the people you choose for twenty four hours, then deleted. We record who viewed it so you can see that list.

Devices and sign ins

A notification token for each device you sign in on, so your phone can be woken. A short record of your devices, so we can email you when a new one signs in. That email includes the time, the device type and the IP address the sign in came from. We read the IP from the connection itself rather than from anything the app claims, so a modified client cannot fake it.

What we never collect

Why we are allowed to hold it

Under UK and EU data protection law every piece of processing needs a lawful basis. Ours:

WhatLawful basis
Your account, and delivering your messages and callsPerformance of a contract. You asked us to run a messenger for you and this is the minimum needed to do it.
Notification tokensPerformance of a contract. Without them your phone cannot ring.
New device emails and abuse handlingLegitimate interests, specifically keeping accounts secure and the service usable. You can object, see your rights below.
Camera, photos, microphone, location, Face IDConsent, given through the iOS permission prompt, withdrawable at any time in Settings.
Keeping records where the law requires itLegal obligation.

Companies that process data for us

Fariin does not own server hardware. These are the services it runs on and what each one touches. Each is bound by a contract that permits them to act only on our instructions and forbids using your data for their own purposes.

ServiceWhat it handles
Google FirebaseAccounts, the message database, file storage. Message contents arrive already encrypted.
Apple Push Notification serviceWaking your iPhone for a message or an incoming call.
CloudflareRelaying calls that cannot connect directly, and serving this website.
LiveKitGroup calls with more than two people.
ResendSending the account emails described above.
GiphyGIF search. What you type into GIF search is sent to Giphy.

Nobody else receives your data. We do not sell it, rent it, trade it, or hand it to advertisers or data brokers. If we are ever served a valid legal order we will comply with it, and what we can hand over is limited to what we hold, which does not include the contents of your messages or calls.

Where your data is held, and transfers

The message database and file storage run in Google's Middle East region. Account emails are processed in Ireland. Call relays run on servers near whoever is calling, including Mogadishu, Djibouti and Nairobi.

That means data about people in the UK or the EU can leave those regions. Where it does, the transfer relies on the UK and EU Standard Contractual Clauses in our agreements with the providers above, or on an adequacy decision where one covers the country in question.

How long we keep things

How it is protected

No system is beyond breaking, and anyone who tells you otherwise is selling something. What end to end encryption buys you is that a breach of our servers still does not expose what you said.

If something goes wrong

If there is a breach that puts your data at risk, we will report it to the relevant supervisory authority within 72 hours of becoming aware of it, as the law requires, and tell you directly and without delay if the risk to you is high. We will say what happened, what was affected, and what to do about it. We will not quietly sit on it.

Deleting your account

You can delete your account from inside the app. We email you, then wait thirty days before erasing anything, so a deletion made in anger or by accident can be undone. Signing back in during those thirty days cancels it.

After thirty days we delete your stories and their media, your profile photo, your account record, and your sign in credentials. Messages you already sent to other people stay on their phones, the way a letter you posted stays with whoever received it.

Your rights

If you are in the UK or the EU, the law gives you all of the following. In practice we honour them for everyone, wherever you live.

Write to [email protected] and we will answer within thirty days. There is no charge. If you are not satisfied with our answer you can complain to your national data protection authority, which in the UK is the Information Commissioner's Office.

Children

Fariin is not intended for children under 13. We do not knowingly hold data about them. If we learn an account belongs to a child under 13 we delete it. If you believe that has happened, write to [email protected].

This website

fariin.com sets no cookies, runs no analytics, and carries no trackers or third party scripts. Nothing here follows you. Our host keeps standard server logs, including IP addresses, for a short period to serve pages and absorb attacks.

Automated decisions

Nothing about your account is decided by an automated system, and there is no profiling.

Who is responsible for your data

Fariin is run by one person rather than a company. They are the data controller for the purposes of the UK and EU rules and can be reached at [email protected]. If a postal address is needed for a formal request, ask and it will be provided. If Fariin becomes a registered company this page will name it.

Changes to this policy

If this changes in a way that affects you, we will tell you in the app before it takes effect, not afterwards. The date at the top always reflects the version you are reading.

Contact

Write to [email protected]. To report abuse, write to [email protected].